Forum Discussion

The_Engima_Code's avatar
The_Engima_Code
Icon for Nimbostratus rankNimbostratus
May 18, 2015

McAfee SIEM and ASM

I am trying to integrate McAfee SIEM and F5 ASM 11.2.1. However, the SIEM doesn't parse the logs correctly. After raising a ticket with McAfee, they said the issue is with the log format which is sending ';' as a delimiter instead of '|'. ASM is managed by customer's 3rd party and they have been interesting to deal with.

 

Below is the snippet of the logs, could you please confirm if the logging format is correct and if we can change the delimiter to '|'

 

<130>May 18 14:37:43 ASM.test.net ASM:ID=17934223281240667815;TYPE=Session Hijacking;DATE=2015-05-18 14:37:43;DEST_IP=10.X.X.X;DEST_PORT=443;GEO=NZ;HEADERS=Host: abcd.com\r\nAccept: text/html,application/xhtml+xml,application/xml;q=0.9,/;q=0.8\r\nConnection: keep-alive\r\nCookie: systemonline=rd1894o00000000000000000000ffff0ae82510o8081; TS23170d=b7a4548f02236bf5190c7a96708fe5af43b1ac33e4d3adb955595077a59b3514f8bf1008; TS553073=b9c1bdd560eba8c7c65346b59981217b361524825b09819e55595073a59b3514f8bf1008fd3b4071173028d4; __utma=18589601.539768155.1431916378.1431916378.1431916378.1; __utmb=18589601.6.10.1431916378; __utmc=18589601; __utmt=1; __utmz=18589601.1431916378.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_2) AppleWebKit/600.3.18 (KHTML, like Gecko) Version/8.0.3 Safari/600.3.18\r\nAccept-Language: ja-jp\r\nReferer: https://xyz.com/system\r\nAccept-Encoding: gzip, deflate\r\nX-Forwarded-For: 1.2.3.4\r\nX-Forwarded-For: 1

 

2 Replies

  • Mahesh, whoever is managing the ASM need to configure the Logging Profile for your ASM policy to be in the format acceptable by McAfee SIEM - if it is a delimiter issue then it can be easily configured in the Logging Profile screen(just change semi-colon to pipe in the Delimiter field).

     

    Only McAfee can tell you what is the correct format their device is expecting - you can them ask the ASM guys to configure the logging profile to match this format.

     

    Hope this helps,

     

    Sam

     

  • Mahesh, whoever is managing the ASM need to configure the Logging Profile for your ASM policy to be in the format acceptable by McAfee SIEM - if it is a delimiter issue then it can be easily configured in the Logging Profile screen(just change semi-colon to pipe in the Delimiter field).

     

    Only McAfee can tell you what is the correct format their device is expecting - you can them ask the ASM guys to configure the logging profile to match this format.

     

    Hope this helps,

     

    Sam